On the Pitfalls of End-to-End Encrypted Communications

Maliheh Shirvanian, Nitesh Saxena, Jesvin James George · 2017

Many widely used Internet messaging and calling apps, such as WhatsApp, Viber, Telegram, and Signal, have deployed an end-to-end encryption functionality. To defeat potential man-in-the-middle attackers against the key exchange protocol, the approach crucially relies upon users to perform a code verification task whereby each user must compare the code (a fingerprint of the cryptographic keys) computed by her app with the one computed by the other user's app and reject the session if the two codes do not match.

Read the paper · More papers on PaperTik